Security and privacyGrid Console reads and orchestrates; the agent provider acts. That split is the whole security story, and it is why so little needs to leave your machine.ArchitectureCOMPONENTDOESGrid ConsoleCard state, stages, boards, memory files, the code index, the licence check.The providerRuns the model, edits files, runs commands. Signed in on its own.ConsequenceNo model call, prompt or API key passes through us.
What stays localAlways local: repositories, worktrees, diffs, transcripts, rewind and action history, the code index. Local until you turn on sync: cards, plans, boards, and encrypted when they do move.What Grid Console sendsFIELDWHYDevice idA random id created on first run, so a licence can be device-bound.Plan idWhich tier the licence is for.VersionSo we can tell you when an upgrade fixes your bug.NeverCode, prompts, transcripts, file names, model keys.
Telemetry and error reportsTelemetry is opt-in, two levels, and never content: level 1 is crash type and version, level 2 adds anonymous feature counts. Settings → Privacy shows exactly what was sent and when.Error reports are built for the alpha and are deliberately manual. Grid Console assembles the report, obfuscating card text, session text and code first, optionally with a blurred screenshot and the last 30 seconds of screen. You read the payload, then either press send or copy it and mail it yourself. Nothing is transmitted without that press.Signed builds and disclosureEvery release and every official plugin is signed, with checksums published next to each download. Report vulnerabilities to security@gridconsole.dev; we reply within three working days.